Executive brief
Adobe Illustrator contains a flaw in how it searches for programs and resources on disk, allowing an attacker to substitute a malicious program that the application will execute with user privileges. An attacker must trick a user into opening a specially crafted file, but once the file is opened, arbitrary code runs without additional interaction. This could allow an attacker to install malware, steal data, or take control of a user's workstation.
Technical details
The vulnerability is an untrusted search path issue affecting Illustrator's resource loading mechanism. When Illustrator searches for critical resources or programs, it does not properly validate the search order or paths used, allowing an attacker to place a malicious binary in a location that is checked before the legitimate one. An attacker must craft a malicious file and trick a user into opening it; upon opening, Illustrator will execute the attacker's code with the privileges of the current user. Versions 29.8.3, 30.0 and earlier are affected. A fix is presumed available in later versions.
Affected products
- Adobe Illustrator 29.8.3, 30.0 and earlier
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory